Holy Cow Studios
Holy Cow Studios
Privacy Policy
Privacy Policy
How we handle personal data, protect your choices, and keep our commitments clear.
How we handle personal data, protect your choices, and keep our commitments clear.
Effective 21 August 2026
Effective 21 August 2026
•
Last updated 21 August 2026
Last updated 21 August 2026
Privacy Policy
Effective date: 21 August 2026 Last updated: 21 August 2026
Holy Cow Studios Private Limited (“Holy Cow Studios”, “we”, “us”, “our”) respects your privacy. This policy explains what personal data we handle, why, who we share it with, how long we keep it, and the rights you have over it.
We have written it to be read, not to be survived. If anything here is unclear, write to us and we will explain it in plain terms.
1. Who we are
Holy Cow Studios Private Limited is the data controller — under India’s Digital Personal Data Protection Act, 2023, the Data Fiduciary — for the personal data described in Part I of this policy.
Grievance Officer
We acknowledge every request promptly and respond within 30 days. That 30-day period runs from when you contact us, not from the next working day — the hours above tell you when someone is at a desk, not when your request starts counting.
2. Scope, and the two different roles we play
This policy covers holycowstudios.in, www.holycowstudios.in, research.holycowstudios.in, our correspondence with you, and participation in our research programmes including the Goa AI Readiness Benchmark.
We handle personal data in two quite different capacities, and your rights differ depending on which applies.
This distinction is not a technicality. When we build an automation for a hotel, the guest data flowing through it belongs to that hotel’s relationship with its guests, not to ours.
This policy does not cover third-party websites we link to. Those have their own policies and we do not control them.
Part I — Data we control
I.1 What we collect, and why
Information you give us
Under the DPDP Act, our lawful ground for each of the above is your consent, given when you choose to submit the information, except where we may process it for the legitimate use of responding to a request you made.
We do not sell personal data. We have never sold personal data. We do not share it for cross-context behavioural advertising.
Information collected automatically
When you visit, we and our providers may record your IP address, browser and device type, referring page, the pages you view, and the dates and times of those visits. This keeps the site working and tells us which research is read. What is stored on your device, and when, is set out in §I.3.
What we do not collect
We do not knowingly collect special-category data — health, biometrics, religious or political views, sexual orientation, or trade-union membership. We do not ask for payment-card details on this website. Please do not send us any of these.
I.2 Our research programme
This section applies if you take part in our research, including the Goa AI Readiness Benchmark. It is a public statement of commitments we hold ourselves to, not boilerplate.
What we collect. Your name, role, employer, contact details and what you tell us in interviews. We also record publicly observable facts about the property or business — published rates, response times, website structure and similar — which we gather without needing your cooperation.
Our commitments.
Findings are published only in aggregate and anonymised. No property and no
individual is identified in any published report without separate, written permission.
Your individual results are confidential and are never shown to a competitor.
Your data belongs to the conversation we had, not to our sales pipeline.
Every audited property receives its own results free and unconditionally,
whether or not it ever becomes a client, and whether or not it wants anything further from us.
You may withdraw at any time, before or after publication, and we will remove
your data from the dataset. Where a finding has already been published in aggregate form and cannot be disentangled, we will tell you so plainly rather than imply otherwise.
Participation is not conditional on buying anything. Declining to buy has no
effect on what you receive.
Legal basis. Consent, which you may withdraw at any time by writing to the Grievance Officer. Where we record only publicly available information about a business, we rely on legitimate interests in conducting research.
I.3 Cookies and similar technologies
Strictly necessary cookies keep the site working. They cannot be switched off and are set without consent, as the law permits.
Analytics cookies (Google Analytics 4, loaded through Google Tag Manager) tell us which pages and papers are read. What happens depends on where you are, and we would rather state that plainly than imply a single rule:
We use Google Consent Mode, so your choice is passed to Google directly and applies from the moment you make it. Withdrawing consent is as easy as giving it, and takes effect immediately.
Our research papers set no analytics cookies at all. On research.holycowstudios.in, wherever you are in the world, measurement is cookieless: we can see that a page was viewed and roughly where from, but nothing is stored on your device, nothing identifies you, and one visit cannot be linked to another.
We use no advertising, marketing or profiling cookies anywhere, in any region. Advertising storage is switched off by default and we have never switched it on.
Your browser can also block or delete cookies. Doing so may stop parts of the site working.
I.4 Who we share it with
We share personal data only with providers who process it on our instructions, and only as far as they need it to do their job.
We may also disclose personal data where we are legally required to — to a court, regulator or law-enforcement authority acting under proper authority — or to establish or defend legal claims. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.
I.5 International transfers
We are based in India. Some providers above are in the United States or the European Union, so your personal data may be transferred outside your country.
Where data protected by the GDPR or UK GDPR is transferred outside the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies. You may request a copy of the safeguards we rely on by writing to the Grievance Officer.
I.6 How long we keep it
When a period ends we delete the data or irreversibly anonymise it.
Part II — Data we process on behalf of clients
When we build, run or support an automation, an AI system or an IT service for a client, personal data may pass through it — the client’s customers, guests, staff or suppliers.
For that data, the client is the controller and we are the processor. We act only on the client’s documented instructions, under a written contract or data processing agreement.
What that means in practice:
We do not decide what that data is used for. The client does.
We do not use it for our own purposes — not for research, not for marketing,
not for training any AI model, not for our benchmarks or case studies. Where we publish a case study, it is agreed in writing with the client first and contains no personal data.
We keep it only as long as the engagement requires, then return or delete it as
the client instructs.
We apply the same security measures described in §III.3.
If we engage a sub-processor, we do so only where the client’s contract permits
and under equivalent obligations.
If you are a customer of one of our clients and want to exercise rights over your data, please contact that organisation — they are the controller and hold the relationship with you. If you contact us instead, we will pass your request on promptly and tell you we have done so, but we cannot act on it directly without the client’s instruction. This is a legal constraint, not an unwillingness to help.
Part III — General
III.1 Your rights
Wherever you live, you may ask us to:
Tell you what personal data we hold about you, and give you a copy
Correct anything inaccurate or incomplete
Delete it, where there is no overriding reason for us to keep it
Restrict or object to how we use it
Port it to another provider in a machine-readable form
Withdraw consent at any time, without affecting anything done before you
withdrew it
Depending on where you live you may also have the right to:
India (DPDP Act 2023): nominate another person to exercise these rights on
your behalf if you die or become incapacitated; use our grievance redressal process before approaching the Data Protection Board of India; and, where we make consent available through a registered Consent Manager, to give, manage, review and withdraw your consent through that Consent Manager
EEA / UK (GDPR): complain to your data protection authority
California (CCPA/CPRA): know, delete, correct, and opt out of sale or sharing —
we do not sell or share personal data, so there is nothing to opt out of — and not be discriminated against for exercising these rights
How to exercise them. Write to gaurav.hooda@holycowstudios.in. We respond within 30 days. We may ask you to confirm your identity first — not to obstruct you, but because handing your data to someone impersonating you would be a worse failure than a delay. Exercising these rights is free.
III.2 Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significant effects.
We advise clients on artificial intelligence, and we use AI tools in preparing our own research and written material. Those tools are not used to make decisions about individuals, and personal data you give us is not used to train any third-party AI model.
III.3 Security
We use HTTPS across all our sites, restrict access to personal data to people who need it, and choose providers who maintain recognised security practices. These are reasonable security safeguards appropriate to the data we hold; they are not a guarantee.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as the law requires — under the DPDP Act, the Data Protection Board of India, and under the GDPR, within 72 hours where the breach is likely to result in a risk to your rights.
III.4 Children
Our services are for businesses and are not directed at children. Under the DPDP Act, a child is anyone under 18. We do not knowingly collect personal data from anyone under 18, we do not knowingly track or behaviourally monitor children, and we do not direct advertising at them. If you believe a child has given us personal data, tell us and we will delete it.
III.5 Other websites, widgets and anything you post publicly
Links. Our sites link to other organisations’ websites. We do not control them and are not responsible for their content or their privacy practices. Check their policies before giving them your data.
Social media links and widgets. Where our site links to or embeds LinkedIn, WhatsApp, X or similar, your interaction with those is governed by that company’s privacy policy, not ours.
Anything you post publicly. If you post a comment, review or message in a public place — including our social media pages — it can be read, copied and used by others. We are not responsible for personal information you choose to disclose publicly.
III.6 Do Not Track and Global Privacy Control
There is no single agreed standard for “Do Not Track” browser signals, and we do not currently respond to them. We do honour the Cookie Settings choice you make on this site, which is the control that actually governs what we collect.
III.7 Business transfers
If our business is sold or reorganised, personal data may transfer to the acquirer, who will remain bound by this policy until you are told otherwise.
III.8 Language
This policy is published in English. On request to the Grievance Officer, we will provide it in any language listed in the Eighth Schedule to the Constitution of India.
III.9 Changes to this policy
We may update this policy. The effective date at the top always shows the current version. If we make a change that materially affects your rights, we will say so prominently on this page and notify subscribers by email. We will not apply a materially different use of data you have already given us without asking you again.
III.10 Governing law
This policy is governed by the laws of India, and the courts at Karnal, Haryana have jurisdiction. This does not remove any right you have to bring a claim, or complain to a regulator, in the country where you live.
III.11 Complaints
Please raise any concern with our Grievance Officer first — we would rather fix it than have you escalate.
If you are not satisfied, you may complain to:
India: the Data Protection Board of India
EEA: the supervisory authority in your country of residence or work
UK: the Information Commissioner’s Office
III.12 Contact
Gaurav Hooda, Grievance Officer Holy Cow Studios Private Limited gaurav.hooda@holycowstudios.in Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India +91 9311421200
·
Legal name: Holy Cow Studios Private Limited
CIN: U72900DL2021PTC378100
Registered office: Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India
Operations: Next to Magsons Supercentre, Dayanand Bandodkar Marg, Miramar, Panaji, Goa 403001, India
Email: office@holycowstudios.in
Telephone: +91 9311421200
·
Name: Gaurav Hooda
Designation: Grievance Officer
Email: gaurav.hooda@holycowstudios.in, or office@holycowstudios.in
Postal address: Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India
Working hours: Monday to Friday, 10:00–18:00 IST, excluding public holidays
· Part I — data we control · Part II — data we process for a client
Whose data: Website visitors, enquirers, subscribers, research participants Our client’s customers, staff or contacts
Our role: Data Fiduciary / controller — we decide why and how Data Processor — we act only on the client’s documented instructions
Who you ask about your rights: Us The client, who is the controller. We will pass on any request we receive
What · When · Why · Legal basis (GDPR)
Name, email, phone, message: You submit the contact form To answer you Legitimate interests / steps prior to a contract
Email address: You subscribe to updates To send you research and updates Consent
Name, email, meeting details: You book a call To hold the meeting Steps prior to a contract
Correspondence and notes: You contact us To maintain a record of our dealings Legitimate interests
Where you are · What we do
European Economic Area and the United Kingdom: Analytics are off until you accept. Nothing is stored on your device before you choose
Everywhere else, including India: Analytics are on by default. You can switch them off at any time using Cookie Settings in the footer
Provider · What they do · Where
Framer B.V.: Hosts and serves this website Netherlands / EU
Google LLC: Google Analytics 4, Google Tag Manager, Google Fonts United States
Cal.com, Inc.: Meeting scheduling United States
Hostinger International Ltd: Email, and hosting for research.holycowstudios.in Lithuania / EU
Data · Retention
Contact-form enquiries that do not become client relationships: 24 months from last contact
Newsletter subscribers: Until you unsubscribe, plus 12 months
Client records: 8 years after the engagement ends, for tax and statutory purposes
Research programme data: Until the study is published, plus 36 months, to allow findings to be checked
Website analytics: 14 months
Privacy Policy
Effective date: 21 August 2026 Last updated: 21 August 2026
Holy Cow Studios Private Limited (“Holy Cow Studios”, “we”, “us”, “our”) respects your privacy. This policy explains what personal data we handle, why, who we share it with, how long we keep it, and the rights you have over it.
We have written it to be read, not to be survived. If anything here is unclear, write to us and we will explain it in plain terms.
1. Who we are
Holy Cow Studios Private Limited is the data controller — under India’s Digital Personal Data Protection Act, 2023, the Data Fiduciary — for the personal data described in Part I of this policy.
Grievance Officer
We acknowledge every request promptly and respond within 30 days. That 30-day period runs from when you contact us, not from the next working day — the hours above tell you when someone is at a desk, not when your request starts counting.
2. Scope, and the two different roles we play
This policy covers holycowstudios.in, www.holycowstudios.in, research.holycowstudios.in, our correspondence with you, and participation in our research programmes including the Goa AI Readiness Benchmark.
We handle personal data in two quite different capacities, and your rights differ depending on which applies.
This distinction is not a technicality. When we build an automation for a hotel, the guest data flowing through it belongs to that hotel’s relationship with its guests, not to ours.
This policy does not cover third-party websites we link to. Those have their own policies and we do not control them.
Part I — Data we control
I.1 What we collect, and why
Information you give us
Under the DPDP Act, our lawful ground for each of the above is your consent, given when you choose to submit the information, except where we may process it for the legitimate use of responding to a request you made.
We do not sell personal data. We have never sold personal data. We do not share it for cross-context behavioural advertising.
Information collected automatically
When you visit, we and our providers may record your IP address, browser and device type, referring page, the pages you view, and the dates and times of those visits. This keeps the site working and tells us which research is read. What is stored on your device, and when, is set out in §I.3.
What we do not collect
We do not knowingly collect special-category data — health, biometrics, religious or political views, sexual orientation, or trade-union membership. We do not ask for payment-card details on this website. Please do not send us any of these.
I.2 Our research programme
This section applies if you take part in our research, including the Goa AI Readiness Benchmark. It is a public statement of commitments we hold ourselves to, not boilerplate.
What we collect. Your name, role, employer, contact details and what you tell us in interviews. We also record publicly observable facts about the property or business — published rates, response times, website structure and similar — which we gather without needing your cooperation.
Our commitments.
Findings are published only in aggregate and anonymised. No property and no
individual is identified in any published report without separate, written permission.
Your individual results are confidential and are never shown to a competitor.
Your data belongs to the conversation we had, not to our sales pipeline.
Every audited property receives its own results free and unconditionally,
whether or not it ever becomes a client, and whether or not it wants anything further from us.
You may withdraw at any time, before or after publication, and we will remove
your data from the dataset. Where a finding has already been published in aggregate form and cannot be disentangled, we will tell you so plainly rather than imply otherwise.
Participation is not conditional on buying anything. Declining to buy has no
effect on what you receive.
Legal basis. Consent, which you may withdraw at any time by writing to the Grievance Officer. Where we record only publicly available information about a business, we rely on legitimate interests in conducting research.
I.3 Cookies and similar technologies
Strictly necessary cookies keep the site working. They cannot be switched off and are set without consent, as the law permits.
Analytics cookies (Google Analytics 4, loaded through Google Tag Manager) tell us which pages and papers are read. What happens depends on where you are, and we would rather state that plainly than imply a single rule:
We use Google Consent Mode, so your choice is passed to Google directly and applies from the moment you make it. Withdrawing consent is as easy as giving it, and takes effect immediately.
Our research papers set no analytics cookies at all. On research.holycowstudios.in, wherever you are in the world, measurement is cookieless: we can see that a page was viewed and roughly where from, but nothing is stored on your device, nothing identifies you, and one visit cannot be linked to another.
We use no advertising, marketing or profiling cookies anywhere, in any region. Advertising storage is switched off by default and we have never switched it on.
Your browser can also block or delete cookies. Doing so may stop parts of the site working.
I.4 Who we share it with
We share personal data only with providers who process it on our instructions, and only as far as they need it to do their job.
We may also disclose personal data where we are legally required to — to a court, regulator or law-enforcement authority acting under proper authority — or to establish or defend legal claims. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.
I.5 International transfers
We are based in India. Some providers above are in the United States or the European Union, so your personal data may be transferred outside your country.
Where data protected by the GDPR or UK GDPR is transferred outside the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies. You may request a copy of the safeguards we rely on by writing to the Grievance Officer.
I.6 How long we keep it
When a period ends we delete the data or irreversibly anonymise it.
Part II — Data we process on behalf of clients
When we build, run or support an automation, an AI system or an IT service for a client, personal data may pass through it — the client’s customers, guests, staff or suppliers.
For that data, the client is the controller and we are the processor. We act only on the client’s documented instructions, under a written contract or data processing agreement.
What that means in practice:
We do not decide what that data is used for. The client does.
We do not use it for our own purposes — not for research, not for marketing,
not for training any AI model, not for our benchmarks or case studies. Where we publish a case study, it is agreed in writing with the client first and contains no personal data.
We keep it only as long as the engagement requires, then return or delete it as
the client instructs.
We apply the same security measures described in §III.3.
If we engage a sub-processor, we do so only where the client’s contract permits
and under equivalent obligations.
If you are a customer of one of our clients and want to exercise rights over your data, please contact that organisation — they are the controller and hold the relationship with you. If you contact us instead, we will pass your request on promptly and tell you we have done so, but we cannot act on it directly without the client’s instruction. This is a legal constraint, not an unwillingness to help.
Part III — General
III.1 Your rights
Wherever you live, you may ask us to:
Tell you what personal data we hold about you, and give you a copy
Correct anything inaccurate or incomplete
Delete it, where there is no overriding reason for us to keep it
Restrict or object to how we use it
Port it to another provider in a machine-readable form
Withdraw consent at any time, without affecting anything done before you
withdrew it
Depending on where you live you may also have the right to:
India (DPDP Act 2023): nominate another person to exercise these rights on
your behalf if you die or become incapacitated; use our grievance redressal process before approaching the Data Protection Board of India; and, where we make consent available through a registered Consent Manager, to give, manage, review and withdraw your consent through that Consent Manager
EEA / UK (GDPR): complain to your data protection authority
California (CCPA/CPRA): know, delete, correct, and opt out of sale or sharing —
we do not sell or share personal data, so there is nothing to opt out of — and not be discriminated against for exercising these rights
How to exercise them. Write to gaurav.hooda@holycowstudios.in. We respond within 30 days. We may ask you to confirm your identity first — not to obstruct you, but because handing your data to someone impersonating you would be a worse failure than a delay. Exercising these rights is free.
III.2 Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significant effects.
We advise clients on artificial intelligence, and we use AI tools in preparing our own research and written material. Those tools are not used to make decisions about individuals, and personal data you give us is not used to train any third-party AI model.
III.3 Security
We use HTTPS across all our sites, restrict access to personal data to people who need it, and choose providers who maintain recognised security practices. These are reasonable security safeguards appropriate to the data we hold; they are not a guarantee.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as the law requires — under the DPDP Act, the Data Protection Board of India, and under the GDPR, within 72 hours where the breach is likely to result in a risk to your rights.
III.4 Children
Our services are for businesses and are not directed at children. Under the DPDP Act, a child is anyone under 18. We do not knowingly collect personal data from anyone under 18, we do not knowingly track or behaviourally monitor children, and we do not direct advertising at them. If you believe a child has given us personal data, tell us and we will delete it.
III.5 Other websites, widgets and anything you post publicly
Links. Our sites link to other organisations’ websites. We do not control them and are not responsible for their content or their privacy practices. Check their policies before giving them your data.
Social media links and widgets. Where our site links to or embeds LinkedIn, WhatsApp, X or similar, your interaction with those is governed by that company’s privacy policy, not ours.
Anything you post publicly. If you post a comment, review or message in a public place — including our social media pages — it can be read, copied and used by others. We are not responsible for personal information you choose to disclose publicly.
III.6 Do Not Track and Global Privacy Control
There is no single agreed standard for “Do Not Track” browser signals, and we do not currently respond to them. We do honour the Cookie Settings choice you make on this site, which is the control that actually governs what we collect.
III.7 Business transfers
If our business is sold or reorganised, personal data may transfer to the acquirer, who will remain bound by this policy until you are told otherwise.
III.8 Language
This policy is published in English. On request to the Grievance Officer, we will provide it in any language listed in the Eighth Schedule to the Constitution of India.
III.9 Changes to this policy
We may update this policy. The effective date at the top always shows the current version. If we make a change that materially affects your rights, we will say so prominently on this page and notify subscribers by email. We will not apply a materially different use of data you have already given us without asking you again.
III.10 Governing law
This policy is governed by the laws of India, and the courts at Karnal, Haryana have jurisdiction. This does not remove any right you have to bring a claim, or complain to a regulator, in the country where you live.
III.11 Complaints
Please raise any concern with our Grievance Officer first — we would rather fix it than have you escalate.
If you are not satisfied, you may complain to:
India: the Data Protection Board of India
EEA: the supervisory authority in your country of residence or work
UK: the Information Commissioner’s Office
III.12 Contact
Gaurav Hooda, Grievance Officer Holy Cow Studios Private Limited gaurav.hooda@holycowstudios.in Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India +91 9311421200
·
Legal name: Holy Cow Studios Private Limited
CIN: U72900DL2021PTC378100
Registered office: Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India
Operations: Next to Magsons Supercentre, Dayanand Bandodkar Marg, Miramar, Panaji, Goa 403001, India
Email: office@holycowstudios.in
Telephone: +91 9311421200
·
Name: Gaurav Hooda
Designation: Grievance Officer
Email: gaurav.hooda@holycowstudios.in, or office@holycowstudios.in
Postal address: Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India
Working hours: Monday to Friday, 10:00–18:00 IST, excluding public holidays
· Part I — data we control · Part II — data we process for a client
Whose data: Website visitors, enquirers, subscribers, research participants Our client’s customers, staff or contacts
Our role: Data Fiduciary / controller — we decide why and how Data Processor — we act only on the client’s documented instructions
Who you ask about your rights: Us The client, who is the controller. We will pass on any request we receive
What · When · Why · Legal basis (GDPR)
Name, email, phone, message: You submit the contact form To answer you Legitimate interests / steps prior to a contract
Email address: You subscribe to updates To send you research and updates Consent
Name, email, meeting details: You book a call To hold the meeting Steps prior to a contract
Correspondence and notes: You contact us To maintain a record of our dealings Legitimate interests
Where you are · What we do
European Economic Area and the United Kingdom: Analytics are off until you accept. Nothing is stored on your device before you choose
Everywhere else, including India: Analytics are on by default. You can switch them off at any time using Cookie Settings in the footer
Provider · What they do · Where
Framer B.V.: Hosts and serves this website Netherlands / EU
Google LLC: Google Analytics 4, Google Tag Manager, Google Fonts United States
Cal.com, Inc.: Meeting scheduling United States
Hostinger International Ltd: Email, and hosting for research.holycowstudios.in Lithuania / EU
Data · Retention
Contact-form enquiries that do not become client relationships: 24 months from last contact
Newsletter subscribers: Until you unsubscribe, plus 12 months
Client records: 8 years after the engagement ends, for tax and statutory purposes
Research programme data: Until the study is published, plus 36 months, to allow findings to be checked
Website analytics: 14 months